MAL-2026-12193
Dashboard / Malicious Package / MAL-2026-12193
MAL-2026-12193
Summary: Malicious code in sextant-relay-darwin-arm64 (npm)
Details: Source: amazon-inspector (43407b6c2131e12ca9f2b18ee48505dbf7541e67aca1b94ad4fdc41e9fbca7c0) The tarball contains a single darwin/arm64 Mach-O Go executable at bin/sextant-relay (~6 MB, stripped) and a minimal package.json with no scripts, main, or bin entry — the package is designed to be selected as a platform-specific optional dependency of a parent package and invoked from there. The binary belongs to project github.com/ddos798/claude_control (referenced from package.json's license field) and its symbol table imports github.com/coder/websocket alongside a handleAgent routine and pseudo-terminal primitives (pty allocation, reader/writer state paired with WebSocket connection state). Together these produce a WebSocket-to-PTY relay: bytes arriving from a remote WebSocket peer are written into a local pty, and pty output is returned over the same socket, giving the operator of the WebSocket server interactive shell control on the host that runs the binary. The package name and description present the binary as a benign 'relay', which does not match its actual behavior. No install-time or import-time execution fires from this sub-package alone; the harm is realized when the parent package invokes the binary on a matching darwin/arm64 host.
Affected packages
Package
Name: sextant-relay-darwin-arm64
Purl: pkg:npm/sextant-relay-darwin-arm64
Affected ranges
Type: N/A
Events:
